when conditionals in RHEL STIG roles fail with ansible-core 2.19+
メンテナーはふだん 3 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 68/100
調査の方向性
redhatofficial.rhel9_stig および redhatofficial.rhel10_stig roles 用に生成された tasks/main.yml から始め、1957 行付近で報告された失敗を含めて、AIDE と audit privileged-functions の条件がどのように生成されるかを調査します。RHEL 9 または RHEL 10 上で ansible-core 2.19+ を使用して roles を実行します。membership tests がブール値として評価され、条件評価の失敗が発生しなければ完了です。
索引モデルが issue の本文から書いたものです。
説明
Description of problem:
Some Ansible when conditionals contain an additional pair of quotes around membership tests. This causes the membership test to be evaluated as a string literal instead of a boolean expression.
Ansible-core 2.19+ requires conditional results to be boolean and the affected tasks fail during conditional evaluation.
The issue is observable in redhatofficial.rhel9_stig and redhatofficial.rhel10_stig roles.
For example, the AIDE condition contains:
find_rules_groups_results is not skipped and "'aide' in ansible_facts.packages"
instead of:
find_rules_groups_results is not skipped and 'aide' in ansible_facts.packages
The audit privileged-functions condition similarly contains:
('"auditd.service" in ansible_facts.services' or '"augenrules.service" in ansible_facts.services')
instead of:
("auditd.service" in ansible_facts.services or "augenrules.service" in ansible_facts.services)
Operating System Version:
RHEL 9 / RHEL 10
Actual Results:
The role fails during conditional evaluation under ansible-core 2.19+ because the quoted membership expression produces a non-boolean result.
[ERROR]: Task failed: Conditional result (True) was derived from value of type 'str' at '/home/app/.ansible/roles/redhatofficial.rhel10_stig/tasks/main.yml:1957:5'. Conditionals must have a boolean result.
Expected Results:
Generate the membership tests as boolean expressions without the additional quoting, allowing the RHEL 9 and RHEL 10 STIG roles to run with ansible-core 2.19+.
- 主要言語
- Shell
- スター
- 2.8k
- フォーク
- 835
- 平均マージ
- 4日 6時間
- マージ済み PR(30日)
- 44
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
ComplianceAsCode/content のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
ComplianceAsCode/content#15152 ·
メンテナーはふだん 3 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
ComplianceAsCode/content#15151 ·
メンテナーはふだん 3 日以内に返信
-
Rules of audit_rules_dac_modification template are misaligned with DISA対応中かも @macko1 が 7 日前に担当しました。 オープンproductization-issue RHEL10 STIG triaged
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
ComplianceAsCode/content#15135 · 担当者 1 名 ·
メンテナーはふだん 3 日以内に返信
-
triaged
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
ComplianceAsCode/content#14994 · コメント 3 件 ·
メンテナーはふだん 3 日以内に返信
-
triaged
難易度 2/5 半日 初心者へのやさしさ 62/100
ComplianceAsCode/content#12264 ·
メンテナーはふだん 3 日以内に返信
ComplianceAsCode/content の issue をすべて見る
似ている issue
-
Feature Needs Triage
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
project-chip/certification-tool#1154 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
beehive-lab/TornadoVM#1151 ·
メンテナーはふだん 1 日以内に返信
-
component/tests
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
NVIDIA/nodewright#735 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
obra/superpowers#2433 ·
メンテナーはふだん 5 日以内に返信